Description
punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent sends mail to an alias and the operator replies, the mail client can send directly to the correspondent from the private FORWARD_TO inbox address, exposing that address. The disclosure is limited to the operator's own email address and does not expose third-party data or provide code execution or authentication bypass. This issue is fixed in version 1.5.0.
Published: 2026-09-17
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive email address disclosure
Action: Apply patch
AI Analysis

Impact

The Cloudflare Email Worker used by PunchIn-App’s punchin-email drops the Reply-To header when forwarding inbound mail, causing the operator’s private FORWARD_TO address to appear in the reply that is sent to external correspondents. Based on the description, it is inferred that this disclosure allows anyone who receives a message from the operator to see the operator’s private email address, potentially enabling unintended direct contact or phishing attempts, but does not provide code execution or access to additional confidential data.

Affected Systems

Versions of punchin-email prior to 1.5.0 are affected. The vulnerability is triggered when handleInbound delivers inbound alias mail with message.forward(), so any instance of the worker that performs this action before the fix will expose the operator’s address. No third‑party data is exposed beyond the operator’s own address.

Risk and Exploitability

The CVSS score of 2.1 indicates low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attack is limited to the operator; an attacker must be able to view the operator’s replies. Based on the description, it is inferred that this is typically possible for any correspondent. There is no remote code execution or elevated privilege exploitation involved.

Generated by OpenCVE AI on September 19, 2026 at 03:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade punchin-email to version 1.5.0 or later so that Reply-To headers are preserved during forwarding.
  • If an immediate upgrade is not possible, modify the worker to use message.send() instead of message.forward() to retain the added Reply-To header.
  • Reconfigure the worker to disable any automatic removal of Reply-To headers when forwarding inbound mail.

Generated by OpenCVE AI on September 19, 2026 at 03:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Punchin-app
Punchin-app punchin-email
Vendors & Products Punchin-app
Punchin-app punchin-email

Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent sends mail to an alias and the operator replies, the mail client can send directly to the correspondent from the private FORWARD_TO inbox address, exposing that address. The disclosure is limited to the operator's own email address and does not expose third-party data or provide code execution or authentication bypass. This issue is fixed in version 1.5.0.
Title punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-To
Weaknesses CWE-200
CWE-201
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Punchin-app Punchin-email
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:22.973Z

Reserved: 2026-06-15T20:16:46.198Z

Link: CVE-2026-54649

cve-icon Vulnrichment

Updated: 2026-09-24T20:50:09.374Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:51.163

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-54649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-201

    Insertion of Sensitive Information Into Sent Data